First published: Thu Sep 20 2018(Updated: )
An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exiv2 Exiv2 | =0.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17282 has been classified as a high-severity vulnerability due to the potential for denial of service from a NULL pointer dereference.
CVE-2018-17282 affects Exiv2 v0.26 by introducing a NULL pointer dereference that can lead to application crashes.
To fix CVE-2018-17282, upgrade Exiv2 to a version later than v0.26 where this vulnerability has been addressed.
The vulnerable version specified in CVE-2018-17282 is Exiv2 v0.26.
CVE-2018-17282 can potentially be exploited remotely if malicious input is processed by Exiv2 v0.26.